CompTIA PenTest+ (PT0-003) practice questions
242 free questions with answers and explanations.
- 201.A penetration tester has gained internal access to a Linux server within a client's network. They need to quickly identify all currently listening network services and the associated processes, including their PIDs and the user running them, to understand the server's attack surface. Which command would provide the MOST comprehensive output for this task?Reconnaissance and Enumeration
- 202.A penetration tester is evaluating a client's external network perimeter. They identify a public-facing web server and want to determine if it is vulnerable to directory traversal by identifying common web server paths and directories. Which Nmap script is most effective for this specific task?Reconnaissance and Enumeration
- 203.A penetration tester is conducting a black-box assessment of a client's web application. They discover that the application has a login form and want to identify valid usernames by observing differences in the application's response to valid versus invalid usernames. Which Metasploit module is specifically designed to enumerate WordPress usernames by observing response differences?Reconnaissance and Enumeration
- 204.A penetration tester is performing reconnaissance against a target organization's internal network. They have obtained a list of IP addresses and want to quickly determine the operating system running on each host without performing a full, intense port scan. Which Nmap option, when combined with a host discovery scan, can provide a reasonable guess of the OS?Reconnaissance and Enumeration
- 205.A penetration tester is performing a black-box assessment of a client's web application. They discover a parameter in a URL that appears to control a file download, e.g., `https://example.com/download?file=report.pdf`. They want to test for Local File Inclusion (LFI) vulnerabilities by attempting to access system files like `/etc/passwd`. Which Burp Suite tool is BEST suited for systematically modifying the 'file' parameter with a list of common LFI payloads?Reconnaissance and Enumeration
- 206.A penetration tester is conducting OSINT against a target organization. They are particularly interested in finding exposed credentials or sensitive information accidentally committed to public code repositories like GitHub. Which specialized tool is designed to automate scanning public repositories for such secrets?Reconnaissance and Enumeration
- 207.A penetration tester is performing an external black-box assessment. They have identified a web server that appears to be running on an unusual port (e.g., 8080) and want to gather as much information as possible about the web server software, including its version, operating system, and any common scripts or directories, without being overly aggressive. Which Nmap command would provide a good balance of detail and stealth for this initial reconnaissance?Reconnaissance and Enumeration
- 208.A penetration tester is performing an internal network assessment. They have compromised a Linux server and want to identify which services are actively listening on TCP and UDP ports, along with the associated process IDs (PIDs) and their corresponding program names. This information will help them understand the server's function and potential pivot points. Which command would provide the most comprehensive details for this task?Reconnaissance and Enumeration
- 209.A penetration tester is performing an internal network assessment and has gained access to a Windows workstation. They need to quickly identify other active hosts on the local subnet without installing any new tools or generating excessive network traffic that might trigger alerts. Which native Windows command-line utility is best suited for this task?Reconnaissance and Enumeration
- 210.A penetration tester is performing a black-box assessment against a client's web application. They discover a login form and want to test for common username enumeration vulnerabilities. They suspect the application might respond differently if a username exists, even if the password is wrong. Which Burp Suite tool is BEST suited for systematically testing a list of usernames against this login form?Reconnaissance and Enumeration
- 211.A penetration tester is performing a black-box assessment against a client's external network. They are attempting to identify hosts that might be running an FTP service. They want to scan for the default FTP port (21/TCP) and quickly gather basic information about any detected service, including its version. Which Nmap command is MOST appropriate for this specific task?Reconnaissance and Enumeration
- 212.A penetration tester is analyzing a web application. They notice that certain HTTP headers, such as 'Server' and 'X-Powered-By', are present in responses and reveal specific technologies. They want to automate the collection of these banners and identify the underlying web server and programming languages. Which Nmap script is specifically designed for this type of web enumeration?Reconnaissance and Enumeration
- 213.A penetration tester is performing reconnaissance against a client's external network. They have identified several public-facing IP addresses and need to determine the operating system and common services running on them, but they want to use a scan that is comprehensive enough to gather detailed information while minimizing the chances of being blocked by basic firewalls that filter typical SYN scans. Which Nmap scan type is most appropriate for this scenario?Reconnaissance and Enumeration
- 214.A penetration tester is performing an internal network assessment. They have compromised a Windows workstation and want to quickly identify other active hosts on the local subnet without triggering excessive alerts. Which command-line tool and technique would be MOST appropriate for a quick, low-impact host discovery?Reconnaissance and Enumeration
- 215.A penetration tester is analyzing a web application using Burp Suite. They notice that a specific parameter, 'itemID', appears to be susceptible to SQL injection. To systematically test for various SQL injection payloads and observe the application's responses, which Burp Suite tool is most appropriate for automating this process?Reconnaissance and Enumeration
- 216.A penetration tester is performing external reconnaissance against a new client. They have identified a few public IP addresses and want to quickly determine which services are listening on common ports and get an initial idea of the operating system without performing a full, aggressive scan. Which Nmap command would achieve this MOST efficiently?Reconnaissance and Enumeration
- 217.During a penetration test, a web server is discovered to be running an older version of Apache. The penetration tester wants to identify if directory listing is enabled or if there are any sensitive files exposed. They also need to understand the directory structure. Which Nmap script, potentially combined with others, would be MOST effective for enumerating web directories and files?Reconnaissance and Enumeration
- 218.A penetration tester is performing a black-box assessment against a client's web application. They discover that the application uses a custom error page that provides little information. To gather more details about potential vulnerabilities, the tester wants to identify common web directories and files that might exist on the server. Which Nmap script is most effective for this purpose?Reconnaissance and Enumeration
- 219.A penetration tester is evaluating a client's web application and discovers several HTTP headers that reveal specific server technologies and version numbers, such as 'Server: Apache/2.4.41 (Ubuntu)' and 'X-Powered-By: PHP/7.4.3'. While this information is useful, the tester wants to confirm if there are any other less obvious headers or HTTP methods supported by the server that could indicate additional vulnerabilities or configuration issues. Which Nmap script would be most effective for this specific task?Reconnaissance and Enumeration
- 220.During a black-box penetration test, an ethical hacker identifies a web server running Apache and wants to enumerate potential hidden directories and files that might expose sensitive information. They need a tool that can perform a dictionary-based brute-force attack against the web server's paths. Which of the following tools is most suitable for this task?Reconnaissance and Enumeration
- 221.A penetration tester is performing an external black-box assessment against a client's web application. They have identified that the web server is running on a non-standard port and is presenting a default Apache welcome page. To further enumerate the web server and identify potential misconfigurations or sensitive files, they wish to perform a comprehensive directory brute-force using a common wordlist. Which Nmap script is specifically designed for this purpose?Reconnaissance and Enumeration
- 222.A penetration tester is evaluating a web application for potential vulnerabilities. They notice that the application uses an older version of Apache and wants to identify if any known directories or files are exposed due to common misconfigurations or default installations. Which Nmap script is specifically designed to enumerate common web directories and files based on known patterns and wordlists?Reconnaissance and Enumeration
- 223.A penetration tester is performing initial reconnaissance against a target organization. They want to identify publicly exposed subdomains and associated IP addresses, but without directly querying the target's DNS servers to avoid detection. Which of the following tools or techniques would be most suitable for this passive enumeration task?Reconnaissance and Enumeration
- 224.A penetration tester is performing OSINT against a target organization. They want to identify publicly available documents, such as PDFs or Word files, that might contain sensitive information like internal usernames, email addresses, or network diagrams. Which reconnaissance technique focuses on extracting metadata from such files found on public websites?Reconnaissance and Enumeration
- 225.A penetration tester is performing external reconnaissance against a client's network. They have identified several public IP addresses and want to quickly determine if any hosts are online without performing deep port scans or generating significant traffic. They need a fast and basic host discovery method. Which Nmap command is most appropriate for this initial stage?Reconnaissance and Enumeration
- 226.A penetration tester is performing OSINT on a target company. They are particularly interested in finding email addresses, employee names, and subdomains associated with the company from publicly available sources. Which open-source intelligence tool is specifically designed to aggregate this type of information from various public data sources?Reconnaissance and Enumeration
- 227.A penetration tester is analyzing a web application using Burp Suite. They notice that a specific parameter in a GET request, `?id=123`, seems to be vulnerable to SQL injection. Before proceeding with manual injection, they want to quickly test a range of common SQL injection payloads against this parameter to see how the application responds, without creating a long list of manual requests. Which Burp Suite tool and attack type would be most efficient for this initial automated testing?Reconnaissance and Enumeration
- 228.A penetration tester is performing OSINT against a target organization. They are specifically interested in identifying any public cloud resources (e.g., AWS S3 buckets, Azure blob storage) that might belong to the company, as these often contain misconfigured or sensitive data. Which specialized tool is designed to enumerate cloud resources based on company names and keywords?Reconnaissance and Enumeration
- 229.A penetration tester has obtained a database dump that includes password hashes in an unknown format. They need to identify the hashing algorithm used to then attempt to crack them. They notice that the hashes are 32 characters long and appear to contain only hexadecimal digits. Which hashcat mode is BEST suited for identifying and cracking such a hash, given its characteristics?Reconnaissance and Enumeration
- 230.A penetration tester has gained initial access to a Windows server and discovered a password hash in the NTLM format. They need to crack this hash to potentially gain access to other systems or escalate privileges. Which tool is specifically designed for high-performance password cracking and supports the NTLM hash type?Reconnaissance and Enumeration
- 231.A penetration tester is performing a black-box assessment against a client's external network. They have identified several public-facing web servers and want to gather information about their SSL/TLS certificates, such as expiration dates, common names, and potentially alternative subject names, which might reveal additional subdomains. Which Nmap script is most suitable for this task?Reconnaissance and Enumeration
- 232.A penetration tester has gained initial access to a Linux server and wants to identify all open network connections and listening services to understand the network footprint of the compromised system. Which command provides the most comprehensive view of active TCP and UDP connections, along with the associated programs and their PIDs?Reconnaissance and Enumeration
- 233.A penetration tester is performing reconnaissance against a dark-web forum known to be frequented by threat actors. They need to gather information about specific users or discussions without actively engaging with the forum or leaving any traces. They are looking for a technique that is completely passive. Which of the following best describes this approach?Reconnaissance and Enumeration
- 234.A penetration tester has identified a target web application that appears to be running on an unusual port, 8443, and uses HTTPS. They want to perform a comprehensive vulnerability scan using Nmap, including service version detection, OS detection, and common script scanning, specifically targeting this port. Which Nmap command would be MOST appropriate?Reconnaissance and Enumeration
- 235.A penetration tester is performing an internal assessment. They have compromised a Windows workstation and want to quickly identify other active hosts on the same local subnet. They need a command that leverages the Windows operating system's native capabilities for host discovery. Which command is most effective for this purpose?Reconnaissance and Enumeration
- 236.A penetration tester is performing reconnaissance against a client's network. They have identified a domain name and want to discover potential subdomains by querying publicly available DNS records and using passive techniques to avoid direct interaction with the target's DNS servers. Which of the following methods is a form of passive subdomain enumeration?Reconnaissance and Enumeration
- 237.A penetration tester is evaluating a client's external network. They want to identify open ports and services, but need to minimize the risk of detection by intrusion detection systems (IDS). Which Nmap scan type is best suited for this objective?Reconnaissance and Enumeration
- 238.During a black-box penetration test, an ethical hacker identifies a web server running Apache. They suspect that the server might have directory listing enabled or contain hidden directories. To efficiently discover these, which technique involves sending requests for common directory names and analyzing the HTTP responses?Reconnaissance and Enumeration
- 239.A penetration tester is conducting reconnaissance against a target organization's web infrastructure. They have identified the main domain and now want to discover subdomains that might not be publicly linked but are still active. Which of the following Nmap scripts is MOST effective for this task?Reconnaissance and Enumeration
- 240.A penetration tester has gained a shell on a Linux server that is restricted from making direct outbound connections to the internet, but can resolve external DNS queries. The tester wants to exfiltrate a small text file containing sensitive data (e.g., /etc/shadow) without attracting suspicion. Which of the following techniques would be MOST effective for this scenario?Post-exploitation and Lateral Movement
- 241.A penetration tester has compromised an internal Windows server and established a Meterpreter session. To ensure persistent access, the tester decides to create a hidden service that will automatically restart if the system reboots. Which Meterpreter command or technique would best achieve this, considering stealth and persistence?Post-exploitation and Lateral Movement
- 242.A penetration tester is performing an internal network assessment. They discover a web application that uses a custom API endpoint for user authentication. The application's server-side code does not properly validate user-supplied input for the 'redirect_to' parameter in the API calls. Which type of attack is MOST likely to be successful against this vulnerability?Attacks and Exploits